Description
Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through <= 3.12.0.
Published: 2025-12-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw in the Custom 404 Pro plugin. An attacker can craft a request that is sent from a victim’s browser, potentially causing the plugin to execute privileged operations with the victim’s credentials. The primary impact is that an attacker can trigger unauthorized actions within the WordPress site using the victim’s authenticated session. This flaw maps to CWE‑352 because it involves accepting unexpected input without proper validation or user confirmation.

Affected Systems

Affected systems include the Kunal Custom 404 Pro plugin for WordPress. Versions from the earliest available release up through 3.12.0 are vulnerable. The vulnerability is listed for all installations of this plugin that have not been updated beyond 3.12.0.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The flaw is not currently in the CISA Known Exploit Vulnerabilities catalog. Because the CSRF flaw requires a victim to be authenticated to WordPress, an attacker’s success depends on obtaining a valid session cookie, either by luring a user to a malicious page or by compromising credentials. An attacker can bypass the plugin’s CSRF protections by submitting forged requests that the browser automatically includes the victim’s cookies with.

Generated by OpenCVE AI on April 29, 2026 at 18:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Custom 404 Pro plugin to the latest stable release, which removes the CSRF flaw.
  • If an upgrade is not immediately possible, disable or remove the plugin until a patch is available.
  • Ensure that all WordPress installations have a current version of the core and other plugins, and enforce strong authentication controls to reduce the risk of compromised user sessions.

Generated by OpenCVE AI on April 29, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Kunal Nagar Custom 404 Pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through 3.12.0. Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through <= 3.12.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 23 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Kunalnagar
Kunalnagar custom 404 Pro
Wordpress
Wordpress wordpress
Vendors & Products Kunalnagar
Kunalnagar custom 404 Pro
Wordpress
Wordpress wordpress

Mon, 22 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Dec 2025 09:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Kunal Nagar Custom 404 Pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through 3.12.0.
Title WordPress Custom 404 Pro plugin <= 3.12.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Kunalnagar Custom 404 Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:04.620Z

Reserved: 2025-10-24T14:24:07.764Z

Link: CVE-2025-62880

cve-icon Vulnrichment

Updated: 2025-12-22T13:54:57.727Z

cve-icon NVD

Status : Deferred

Published: 2025-12-22T10:16:01.030

Modified: 2026-04-23T15:34:42.143

Link: CVE-2025-62880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:45:17Z

Weaknesses